No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:espressif:esp-idf:5.5.4:*:*:*:*:*:*:* cpe:2.3:a:espressif:esp-idf:6.0:*:*:*:*:*:*:* |
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Espressif
Espressif esp-idf |
|
| Vendors & Products |
Espressif
Espressif esp-idf |
Wed, 10 Jun 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware peripherals (AES, SHA, ECC, HMAC, SPI, MMU, WDT) and to the security feature like attestation, OTA updates, secure storage. This issue has been patched in versions 5.5.5 and 6.0.1. | |
| Title | ESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service Wrappers | |
| Weaknesses | CWE-20 CWE-787 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-10T13:00:35.618Z
Reserved: 2026-05-11T20:50:30.540Z
Link: CVE-2026-45328
Updated: 2026-06-10T13:00:28.968Z
Status : Analyzed
Published: 2026-06-10T02:16:32.687
Modified: 2026-06-11T18:15:51.000
Link: CVE-2026-45328
No data.
OpenCVE Enrichment
Updated: 2026-06-10T03:30:16Z